Bishop Fox researchers have confirmed that three patched Ubiquiti UniFi OS Server vulnerabilities (CVE-2026-34908/34909/34910) chain into an unauthenticated root RCE. No credentials or user interaction required — and there’s no authentication log trail to detect it.
Cisco disclosed its seventh exploited SD-WAN zero-day of 2026. CVE-2026-20245 allows root-level command execution with no patch available yet. Here’s what organizations need to know and do right now.